GDPR consulting covers everything from a one-page checklist to a six-figure transformation, and the gap between what's sold and what an SME actually needs is wide. Most SMEs don't need a sprawling project; they need a documented baseline, a few gaps closed, and someone accountable for keeping it current. This guide covers what good GDPR consulting looks like, the difference between a consultant and a DPO, and what to avoid paying for. For the function that combines advice with accountability, see the external DPO pillar.
- What most SMEs need: a baseline (ROPA, notice, DPAs, TOM), gaps closed, and ongoing ownership.
- A consultant advises; a DPO is a defined legal function with independence and contact-point status.
- Be wary of open-ended retainers, enterprise-grade processes, and deliverables you can't maintain.
What Good GDPR Consulting Actually Delivers
What should I be paying for?
Concrete, usable outputs, not a report that sits in a drawer:
- A complete ROPA and a privacy notice that covers your processing purposes and tools.
- Signed DPAs and a specific TOM document.
- A short, prioritised gap list - highest-risk first.
- A maintainable process, so the work doesn't decay after the engagement ends.
If a proposal doesn't translate into documents you can produce in an audit, it isn't solving your problem.
Consultant vs. DPO
Aren't they the same thing?
No, and the distinction matters. A GDPR consultant provides advisory services on a project basis. A Data Protection Officer is a legally defined function (GDPR Art. 37-39): independent, protected from dismissal for doing the job, and the formal contact point for supervisory authorities and data subjects. If you're legally required to appoint a DPO, a consultant relationship alone does not satisfy that obligation - you need the function, not just the advice.
What to Be Wary Of
Where does GDPR consulting get oversold?
- Open-ended retainers with no defined deliverable - pay for outputs, not hours.
- Enterprise processes for a 40-person company - disproportionate documentation you'll never maintain.
- A report with no implementation - findings without fixed gaps don't reduce risk.
- No SME references - a consultant who only works with corporates will over-engineer your setup.
- "Certified" with nothing to show - ask for the qualification (e.g. CIPP/E) and SME references before signing.